Risk management is a complex topic and, fortunately, organizations don’t need to design their own risk management processes from the ground up. Risk management frameworks provide proven, time-tested techniques for performing enterprise risk management. In this video, learn about the value of using a risk management framework and explore the commonly used NIST 800-37 risk management framework.
- [Instructor] Risk management is…a complex topic.…And fortunately organizations don't need…to design their own…risk management processes from the ground up.…Risk management frameworks provide proven,…time tested techniques for performing…enterprise risk management.…One of the most widely used risk management…frameworks was developed by the…National Institute of Standards and Technology,…a U.S. Federal Government agency.…The NIST process is mandatory for many…government computer systems.…
But private organizations have also widely…adopted it because they find it…a helpful approach.…The framework is found in…this special publication 800-37.…This document runs over 60 pages and includes…great detail in the framework that is good…reading for anyone involved in risk management.…The publication is available for free…on NIST's website.…For our purposes an overview of the…six steps in the process will be more than…enough to prepare for the exam.…This diagram shows the six steps involved in…risk management according to NIST.…
- Risk management actions
- Ongoing risk management
- Risk management frameworks
- Scanning for threats and vulnerabilities
- Advanced vulnerability scanning
- Monitoring log files
- Code review and code tests
- Test coverage analysis
Skill Level Intermediate
Q: This course was updated on 05/18/2018. What changed?
A: New videos were added that cover identifying threats, understanding attacks, technology and process remediation, remediating vulnerabilities, and security monitoring. In addition, the following topics were updated: risk management and monitoring log files.
Insights from a Cybersecurity Professionalwith Mike Chapple32m 15s Intermediate
1. Risk Management
2. Threat Modeling
3. Threat Assessment
4. Remediating Vulnerabilites
5. Security Monitoring
6. Software Testing
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.